Themify Builder WordPress Plugin Authorization Bypass Vulnerability Allowing Arbitrary Stylesheet Modification

Vulnerability

A vulnerability exists in the Themify Builder plugin for WordPress, allowing authorization bypass in all versions up to and including 7.7.7. The issue arises because the plugin fails to properly verify user authorization for certain actions. This flaw enables authenticated attackers with subscriber-level access or higher to overwrite or delete the CSS stylesheet files of arbitrary posts, including private and draft posts belonging to other users. Additionally, the vulnerability allows modification of font options within the plugin's scope. The required CSRF nonce, 'tf_nonce', is easily accessible to any authenticated user on public front-end builder pages.

Impact

Exploitation of this vulnerability could lead to unauthorized modification or deletion of CSS files for various posts, potentially disrupting the site's styling and layout. Furthermore, according to Wordfence, this vulnerability could be exploited to execute arbitrary code.

Reproduction

To reproduce this vulnerability, an authenticated user with subscriber-level access or higher can send a request to the 'tb_generate_on_fly' AJAX action. This request can include the 'bid' parameter specifying the post ID of the target post whose stylesheet is to be modified or deleted. The 'tf_nonce' parameter must also be included to pass the CSRF protection.

Remediation

Users are advised to update the Themify Builder plugin to version 7.7.8 or later.

Added: Jul 16, 2026, 9:35 AM
Updated: Jul 16, 2026, 9:35 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
6.0
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.